DeFi Wallet Safety & Token Permission Guide
Understand wallet connections, token approvals, transaction signatures, and the security checks to make before a DeFi swap.
Start with the request in your wallet
A wallet prompt is an authorization decision. Read what action is being requested, which account and network are active, and where the transaction or permission points. A familiar website name or token symbol is not enough to establish the identity of a contract or asset.
Use the official project source to verify addresses and documentation. A link in an advertisement, unsolicited message, or token description can lead elsewhere. Never disclose your recovery phrase or private key to a website, support contact, or person offering to fix a transaction.
Connections, approvals, and signatures do different things
Connecting a website
A wallet connection lets an application request information and actions from your wallet. The permissions depend on the wallet and connection method. A connection is not the same as transferring tokens or granting an ERC-20 allowance.
Granting a token allowance
An allowance authorizes a specified spender to move an amount of a particular token under that token’s rules. Review the spender and amount. Some workflows request a large allowance so future actions do not need a new approval; the convenience also changes the permission you leave in place.
Signing a message
A signature can authorize meaningful actions even when there is no immediate gas charge. Token permits and order signatures have fields that affect what can happen later. Read the domain, spender or intended recipient, amount, nonce, and timing conditions as applicable to the scheme.
Review the transaction as a whole
- Confirm the chain and token contract or mint, rather than relying on a ticker.
- Check input, expected output, and the execution boundary.
- Review the recipient and transaction destination.
- Verify the spender independently of the transaction target when the integration separates them.
- Understand any intermediate bridge, asset, or program in the route.
- Check the completed transaction and resulting balances after submission.
Transaction simulation and readable wallet warnings can improve visibility, but they do not eliminate contract risk or guarantee an outcome. If the decoded request does not match your intention, resolve the discrepancy before authorizing it.
Disconnecting is not the same as revoking
Disconnecting an application in your wallet generally ends the website’s connection. It does not by itself remove an on-chain token allowance. Reviewing and revoking an allowance is a separate action, and an on-chain revocation may require a network fee.
Read the token approvals guide for the difference between ordinary approvals, permits, deadlines, and remaining allowances.
Know the limits of protective settings
A tight slippage setting can make some unwanted execution outcomes fail, while also increasing the chance that changing conditions cause a legitimate attempt to revert. Private transaction submission and other MEV-aware workflows depend on their design and coverage. None turns an unknown token or contract into a risk-free interaction.
The MEV field note explains transaction ordering and sandwich attacks. The cross-chain guide adds the dependencies that appear when a route spans networks.